Results 1 to 7 of 7

Thread: Please help me(New virus i Guess)

  1. #1
    Honorary Argentinian Senior Member Gyroball Champion, Karts Champion Caius's Avatar
    Join Date
    Aug 2006
    Location
    I live in my home, don't you?
    Posts
    8,114

    Default Please help me(New virus i Guess)

    Hello,

    Im needing urgent help with my pc.This virus is really annoying.
    I dont know how this virus came to my pc.
    It activates itself every 20 min(not sure) and It closes all the windows and starts to make very strange things.

    I had found rundll32.exe as a process when this attack started.I closed it(witht the keyboard), and everything came to normallity.

    Im not sure WTF is going on here.

    Really urgent help i need.




    Names, secret names
    But never in my favour
    But when all is said and done
    It's you I love

  2. #2
    Amphibious Trebuchet Salesman Member Whacker's Avatar
    Join Date
    Nov 2006
    Location
    in ur city killin ur militias
    Posts
    2,934

    Default Re: Please help me(New virus i Guess)

    Get a good virus scanner.

    Also consider that you might have been hit with a bad rootkit, if your virus scanner turns up little or nothing. If that's the case, try to back up what you can, and then do (or have someone who knows how to) a full low level reformat and reinstall of your OS. Sorry, but that's the only surefire way of getting rid of a rootkit no matter what people will tell you, those "cleaners" and "removers" only do a halfassed job, and most of the time the damage is already pretty extensive.


    "Justice is the firm and continuous desire to render to everyone
    that which is his due."
    - Justinian I

  3. #3
    Needs more flowers Moderator drone's Avatar
    Join Date
    Dec 2004
    Location
    Moral High Grounds
    Posts
    9,278

    Default Re: Please help me(New virus i Guess)

    Search your registry for rundll32.exe. You should find 1 or more entries that point you to a dll file somewhere, probably in your system32 folder. Boot your PC in safe mode, delete the registry entries, and delete the file being executed. I don't think there are any normal system tasks that use rundll32. This might do it.
    The .Org's MTW Reference Guide Wiki - now taking comments, corrections, suggestions, and submissions

    If I werent playing games Id be killing small animals at a higher rate than I am now - SFTS
    Si je n'étais pas jouer à des jeux que je serais mort de petits animaux à un taux plus élevé que je suis maintenant - Louis VI The Fat

    "Why do you hate the extremely limited Spartan version of freedom?" - Lemur

  4. #4
    Guest Stig's Avatar
    Join Date
    Sep 2006
    Location
    At the bar
    Posts
    4,215

    Default Re: Please help me(New virus i Guess)

    Don't delete rundll32.exe, it's required for your PC to function

    Do a search for it, it should be placed under C:\Windows\System32
    if it's somewhere else as well delete those.

    I have StartUpMonitor which monitors new programs, and whenever I want to install something it gives a pop up that rundll32.exe wants to start that install.

  5. #5
    Toh-GAH-koo-reh Member Togakure's Avatar
    Join Date
    Sep 2003
    Location
    Zen Garden
    Posts
    2,734

    Default Re: Please help me(New virus i Guess)

    I did a quick Google on rundll32.exe, and found this article, which speaks to "imposters" of the legit file. Scroll down the page to read about them. Perhaps investigating along these lines will identify the true culprit.

    http://www.pcreview.co.uk/startup/rundll32.exe.php

    This was only one of many returned links from Google. Whenever I find an executable runnning in Processes that I don't recognize or understand, I Google it and read up. I've found this quick check to be enlightening in most cases.

    StartupMonitor, Sygate Firewall, AVG Antivirus, Spwyware Blaster, and Spybot--all free for personal use--have kept me problem free since I picked up this new PC. That, and being careful about where I surf. Consider using these or similar products available via the 'net to reduce risk of infections.
    Be intent on loyalty
    While others aspire to perform meritorious services
    Concentrate on purity of intent
    While those around you are beset by egoism


    misc kanryodo

  6. #6
    Honorary Argentinian Senior Member Gyroball Champion, Karts Champion Caius's Avatar
    Join Date
    Aug 2006
    Location
    I live in my home, don't you?
    Posts
    8,114

    Default Re: Please help me(New virus i Guess)

    The problem seemed to leave.

    It was strange.Thanks for the help given anyway.




    Names, secret names
    But never in my favour
    But when all is said and done
    It's you I love

  7. #7
    Needs more flowers Moderator drone's Avatar
    Join Date
    Dec 2004
    Location
    Moral High Grounds
    Posts
    9,278

    Default Re: Please help me(New virus i Guess)

    Quote Originally Posted by Stig
    Don't delete rundll32.exe, it's required for your PC to function

    Do a search for it, it should be placed under C:\Windows\System32
    if it's somewhere else as well delete those.

    I have StartUpMonitor which monitors new programs, and whenever I want to install something it gives a pop up that rundll32.exe wants to start that install.
    Just to clarify, I didn't mean delete rundll32.exe, but to delete the dll library it is kicking off in the registry entry.

    All's well apparently, which is good news.
    The .Org's MTW Reference Guide Wiki - now taking comments, corrections, suggestions, and submissions

    If I werent playing games Id be killing small animals at a higher rate than I am now - SFTS
    Si je n'étais pas jouer à des jeux que je serais mort de petits animaux à un taux plus élevé que je suis maintenant - Louis VI The Fat

    "Why do you hate the extremely limited Spartan version of freedom?" - Lemur

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  
Single Sign On provided by vBSSO